GHSA-vrcf-g539-x6h3
CRITICALCVE-2019-17206Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.
- Affected
- < 0.3.0
- Fixed in
- 0.3.0
- Weakness
- CWE-502
- Published
- 2019-11-20
- Source
- github